Skip to main content

WhatsApp Web gets a browser extension to beef up security

WhatsApp on the Web is a convenient way to access the messaging service on a desktop, without the hassle of installing an app. However, with the web, there’s always a risk of bad actors trying to trick users. With that in mind, WhatsApp is now offering a browser extension that verifies if users are on the authentic web version, or if they are on a tampered page that can steal data and install malware among other evil deeds.

How to use it

The process of using the browser extension-based security system is easy. Just go to the Chrome web store and search for Code Verify, hit the blue Add to Chrome button, and you’re good to go. As of now, Code Verify only works on Chrome, Edge, and Mozilla Firefox, but a version tailored for Safari is also in the development phase.

Recommended Videos

Once the browser extension has been installed and pinned to the toolbar, it will start doing its code verification job automatically every time users visit the WhatsApp Web page. And to inform users about the activity status, a color-code indicator system has been put in place. A green icon means everything is fine and there are no security risks.

The color coding system put in place for Code Verify on WhatsApp Web.
Image used with permission by copyright holder

If the Code Verify icon shows an orange circle with a question mark, it is a sign that the network request was timed out. An orange alert means the network connection might be stable or something is interfering with the verification process. To fix it, try reloading the page, changing the Wi-Fi network, or pausing other browser extensions.

Please enable Javascript to view this content

A red indicator with an exclamation mark is a sign that the source code couldn’t be verified, and that’s a possible security risk. In such a scenario, disable the other extensions and reload the WhatsApp Web page to see if the warning sign goes away.

Meta assures that the Code Verify extension doesn’t interfere with the privacy aspect. It won’t log any activity data, collect metadata, or access any of the user information on its own. More importantly, the extension doesn’t let anyone take a peek at the messages as they are end-to-end encrypted, just the way they are on the mobile app.

How it works

The functional template for WhatsApp Web
Image used with permission by copyright holder

Created in collaboration with Cloudflare, Code Verify relies on a security feature called subresource integrity that will check resources on the entire webpage. At the heart of the browser is a hash matching system, which also forms the backbone of Apple’s iCloud photo scanning system for CSAM detection.

“Whenever the code for WhatsApp Web is updated, the cryptographic hash source of truth and extension will update automatically as well,” Meta says in its announcement. The idea is to automate the process of hash matching, and then deploy it on a scale for hundreds of millions of WhatsApp users. Additional in-depth technical details about the Code Verify extension can be found here.

Nadeem Sarwar
Nadeem is a tech journalist who started reading about cool smartphone tech out of curiosity and soon started writing…
What is WhatsApp? How to use the app, tips, tricks, and more
WhatsApp logo on a phone.

There’s been no shortage of instant messaging apps over the past decade, as the rise of advanced smartphone platforms has created the need for more sophisticated ways to communicate than traditional SMS text messages allowed for.

In fact, the Apple App Store and Google Play Store are both littered with apps that promised to be the next big thing in mobile communications. Yet, many of those fell by the wayside as they failed to achieve the critical mass of users needed to make them useful. After all, apps designed for communicating with others don’t do you much good unless enough folks are using them. Luckily, WhatsApp made our list of the best iPhone Apps and our infamous list of the best Android apps out there.

Read more
You’ll soon be able to use WhatsApp on more than one phone
Two phones on a table next to each other. One is showing the WhatsApp logo, and the other is running the WhatsApp application.

WhatsApp, one of the most used messaging services in Europe and parts of Asia, is about to close a major flaw. As spotted by the sleuths over on WABetainfo, the company is planning an update that will allow the use of a secondary device -- including another phone or tablet. Currently, WhatsApp only allows phone users to link their account via its web or desktop clients.

The new feature is dubbed companion mode. Once it rolls out, you'll have a workflow that's quite similar to setting up WhatsApp Web or WhatsApp on the desktop. Rather than entering a number, you'll be able to scan a QR code with your main phone to log in to your existing WhatsApp account.

Read more
WhatsApp is copying two of Zoom’s best video-calling features
Call Links by WhatsApp

WhatsApp is taking a couple of pages out of Zoom's playbook. The Meta-owned company is rolling out the Call Links feature, making it easier for people to join audio and video calls with just one tap on the phone screen.

Mark Zuckerberg announced the new feature in a Facebook post on Monday morning. Starting this week, WhatsApp users will be able to tap the Call Links option within the Calls tab and create a link for audio or video calls to send to their friends and family, who will then tap on the link and join the call from there.

Read more